-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat Kiali for OpenShift Service Mesh 2.0 security update Advisory ID: RHSA-2022:5913-01 Product: Red Hat OpenShift Service Mesh Advisory URL: https://access.redhat.com/errata/RHSA-2022:5913 Issue date: 2022-08-08 CVE Names: CVE-2022-31129 ===================================================================== 1. Summary: An update for openshift-istio-kiali-rhel8-container is now available for OpenShift Service Mesh 2.0. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat Kiali for OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation. This advisory covers containers for the release. Security Fix(es): * moment: inefficient parsing algorithm resulting in DoS (CVE-2022-31129) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2105075 - CVE-2022-31129 moment: inefficient parsing algorithm resulting in DoS 5. JIRA issues fixed (https://issues.jboss.org/): OSSM-1826 - Rebuild Kiali Server container 1.24 to pick up base image CVE fixes 6. References: https://access.redhat.com/security/cve/CVE-2022-31129 https://access.redhat.com/security/updates/classification/#moderate 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYvD8NdzjgjWX9erEAQhH/A//dkJC9hOk1DuHGoeP63G+pANu++mC9CUC MOg7X4rAq8K70dHHRaUsQj7GNf/waAh+z2BRTump8zNBA0QV9psNQFunSbvGLT0F ImfhaZtXvotCEB/Dv9EdnQu04MuoXNTYXYJilAr7kpzll6tu2lNh4Q/lTPo4nFvs uI6s0sop4wWnBsrWHVKbVLCKhtrZJCsI0xd5r36nGbBx80AL3wYaDmyu4ZiLEPTX 3600Bf13cg9s1fbk+lUwVhby9WyTJi/fUSxyBlUyDxYX6LTeyPl7rgt1VH9nH9e9 JevKENtBYAyvfvpajxg3r2XeQrE+WJwEOQVMQVtSDXW01rHzC4oRNT4/7oOmcvem vvCj9eWarYtILH/RaRBIslU/ic9xb0P+cOp+y3WQ/aebczDZXt8jOBRfk99sGdjT HdAlHJ3LuqsZUElhrV8RDh4371IaEFk18Y4cDp1KeZH0JMTTlMUUm5hZN7jL845Z N45BY0nt+f82WB2tm5uN8aUFw6qz9vOhWiqOR5oYwZYUrble68qUbffMKW52dKEv KxIyyf5Xel2MDueupLpPqSKbc1Btu1/5E/h6YSxanPZjh1S2nnC6CkCau5A94Pge RE0e+g1+NPoNW4ORzhssve+Rp517sQIx3XTinlUiQTD4NgJojb065+CIsj4aW+eN HDishDluEdU= =JCIa -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce